---
title: "How To Use Netcat and Level-Up Your Networking Skills!"
description: "Learn how to use Netcat to enhance and level-up your networking and debugging skills with this powerful networking utility!"
canonical: "https://adamtheautomator.com/how-to-use-netcat/"
---

# How To Use Netcat and Level-Up Your Networking Skills!

> Learn how to use Netcat to enhance and level-up your networking and debugging skills with this powerful networking utility!

Source: https://adamtheautomator.com/how-to-use-netcat/

---

ATA Learning

Tap to hide

[

ATA Learning

](/)

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Search for:  

*   [](https://twitter.com/adbertram)
*   [](https://github.com/Adam-the-Automator)
*   [](https://www.linkedin.com/company/adam-the-automator-llc)
*   [](/feed/)

![How To Use Netcat and Level-Up Your Networking Skills!](https://adamtheautomator.com/wp-content/uploads/2022/05/How-To-Use-Netcat-and-Level-Up-Your-Networking-Skills.jpg)

# How To Use Netcat and Level-Up Your Networking Skills!

[![](https://secure.gravatar.com/avatar/2788bb1a3f735603f81eca51d68daec56a9d97e805a10268fb2c20afcc76b81b?s=192&d=mm&r=g)Nicholas Xuan Nguyen](https://adamtheautomator.com/author/nicholas-xuan-nguyen/)10 June 20228 min. read

Categories: [Information Security](/category/infosec/)

Tags:[Networking](/tag/networking/)

Table of Contents

*   [Prerequisites](#prerequisites)
*   [Scanning for Open Ports](#scanning-for-open-ports)
*   [Sending Files Securely Between Hosts](#sending-files-securely-between-hosts)
*   [Sending Directories to Another Host](#sending-directories-to-another-host)
*   [Sending Entire Disk or Partition to Another Host](#sending-entire-disk-or-partition-to-another-host)
*   [Creating a Minimal Webserver](#creating-a-minimal-webserver)
*   [Conclusion](#conclusion)

Managing networks and monitoring traffic data flow between systems sounds intimidating. Well, not unless you know how to use [Netcat](https://www.mvps.net/docs/what-is-netcat-and-how-to-use-it/).

Netcat is a command-line tool that you can use for various purposes, such as port scanning, file transfers, and creating a minimal webserver to test connection activities. And in this tutorial, you’ll learn to take advantage of Netcat as you go over some of the most common use cases for Netcat.

Ready? Read on and kick your networking skills up a notch!

## Prerequisites

This tutorial will be a hands-on demonstration. If you’d like to follow along, be sure you have the following.

*   Two Linux machines: One (ubuntu1) acts as the receiving host, and another (ubuntu2) serves as the sending host – This tutorial uses [Ubuntu](https://adamtheautomator.com/install-ubuntu/) 20.04 for both machines.

Related:[How to Install Ubuntu 20.04 \[Step-by-Step\]](https://adamtheautomator.com/install-ubuntu/)

*   [Netcat](https://www.cyberithub.com/how-to-install-netcat-command-on-linux-ubuntu/) and [bzip2](https://howtoinstall.co/en/bzip2) installed on both machines.

## **Scanning for Open Ports**

Ports are the doorways that allow network traffic to enter and exit a machine. When a port is closed, no service is listening on that port, and no traffic can pass through. But if the port is open, your network is subject to attacks.

If you’d like to check if a specific port is open on a machine patch for any security vulnerabilities, Netcat is up to the task. As a pentester, you need to know which ports are open to conducting your attack. Whatever the reason might be, scanning for open ports is a common need.

The basic syntax for port scanning using Netcat is as follows where:

*   `host` – is the IP address or hostname of the machine you want to scan.
*   `startport` – is the starting port number.
*   `endport` – is the ending port number.

```bash
netcat options host startport-endport
```

> _he netcat command has an alias of nc, which comes in handy to shorten commands. But this tutorial uses netcat for proper documentation._

SSH to your sending host (ubuntu2) and run the following command to scan for open ports between ports `1-100`.

> _Throughout this tutorial, replace 149.28.86.131 with your sending host’s IP address._

Related:[Leverage SSH and PowerShell to Securely Transfer Files Now](https://adamtheautomator.com/powershell-ssh/)

In most cases, the `1-100` port range is sufficient. Most of the services use default port numbers that generally fall in this range, such as `22` for SSH, `80` for HTTP, etc.

The list below explains each of the flags that control the port scan’s behavior:

*   `-z` (zero I/O modes) – Netcat will not read from or write to the network connection. This option makes the scanning process faster.
*   `-n` – Tells Netcat to disable DNS lookup to avoid delays.
*   `-v` – Makes Netcat show all port scanning processes in detail.

```bash
netcat -z -n -v 149.28.86.131 1-100
```

You can see below that the connection to port **22** (SSH) succeeded, but all the other ports failed.

![How to Use Netcat : Scanning for Open Ports](https://adamtheautomator.com/wp-content/uploads/2022/05/image-605.png)

How to Use Netcat : Scanning for Open Ports

Since the `netcat` command lists all scanned ports, you get lots of information and some you don’t need. In that case, run the below command, piping the `grep` command. This command filters out only the open ports with the `“succeeded!”` message at the end, as shown below.

```bash
netcat -z -n -v 149.28.86.131 1-100 2>&1 | grep succeeded
```

Related:[How to Search via Grep with Regex](https://adamtheautomator.com/grep-with-regex/)

Below, you can see that port 22 is open for SSH connection as expected.

![Filtering the Successful Port Connection](https://adamtheautomator.com/wp-content/uploads/2022/05/image-606.png)

Filtering the Successful Port Connection

## Sending Files Securely Between Hosts

Aside from port scanning, Netcat makes it possible to securely transfer files between two machines. Netcat uses the TCP protocol for file transfer, which is more reliable than UDP.

The basic syntax for sending a file using Netcat is as follows:

```bash
netcat options host port filename
```

To send files from your host to another machine:

1\. Run the below command to start listening on port 4444 on the receiving host (ubuntu1).

This command doesn’t have an output, but the options below affect how the command sets the listening port:

*   `-l` – tells `netcat` to listen for an incoming connection on the specified TCP port. The port can be any number you want, but make sure other services are not using your preferred port.
    
*   `> - tells netcat to redirect all incoming data to a file on the specified path (ata_file).`
    

```bash
netcat -l 4444 > ata_file
```

> _Only the root user can bind to ports lower than 1000, so you must select a port larger than 1000 as a non-root user. If you try to use a port number lower than 1000 as a non-root user, you’ll get the following error._

![Getting “Permission denied” Error When Using Port Lower Than 1000](https://adamtheautomator.com/wp-content/uploads/2022/05/image-607.png)

Getting “Permission denied” Error When Using Port Lower Than 1000

2\. On the sending host (ubuntu2), run the following echo command, which doesn’t have an output but creates a file called ata\_file with Hello from ATA as the content.

```bash
echo "Hello from ATA" > ata_file
```

3\. Now, run the netcat command below to send _ata\_file_ to the receiving host (ubuntu1). Make sure that you use the same port number on the receiving host (4444) as the sending host.

This command doesn’t have an output, but the < option tells netcat to take the input from the specified file.

```bash
netcat 149.28.86.131 4444 < ata_file
```

4\. Lastly, switch to the receiving host (ubuntu1) and run the cat command below to check the content of the ata\_file.

```bash
cat ata_file
```

You can see the Hello from ATA message below indicating the transfer worked.

![Verifying the Transfer Worked](https://adamtheautomator.com/wp-content/uploads/2022/05/image-608.png)

Verifying the Transfer Worked

## Sending Directories to Another Host

So far, you’ve successfully sent a single file from one host to another. But what if you like to send an entire directory with all its subdirectories and files instead? Netcat can send directories too!

Suppose you have a backup directory called _apache\_backup_ on the sending host (ubuntu2). You’ll have to compress the directory first, then send and extract the directory to the receiver host (ubuntu1).

1\. On the receiving host (ubuntu1), run the following command to create a new directory called apache\_backup and move (cd) into that directory.

```bash
mkdir apache_backup && cd apache_backup
```

![Creating the apache\_backup Directory](https://adamtheautomator.com/wp-content/uploads/2022/05/image-609.png)

Creating the _apache\_backup_ Directory

2\. Next, run the below command to start listening on port 4444 and extract compressed files the sending host (ubuntu2) sends to the receiving host (ubuntu1).

This command doesn’t have an output, but the tar xf – flags take the input from the Netcat (standard input) and extract all the files into the current directory.

```bash
netcat -l 4444 | tar xf -
```

3\. On the sending host (ubuntu2), run the following commands to create a directory (apache\_backup), some text files, and send them to the receiving host (ubuntu1).

These commands don’t have an output, but you’ll verify if the transfer worked in the following step.

```bash
# Creates an apache_backup directory and some text files inside
mkdir apache_backup && cd apache_backup && touch ata{1..5}.txt
# Compresses the working directory and sends it to the receiving host
tar cf - . | netcat 149.28.86.131 4444
```

4\. Finally, switch to the receiving host (ubuntu1), press Ctrl+C to stop listening to port 4444, and run the ls command to list the files inside the _apache\_backup_ directory.

```bash
ls
```

As you can see below, the _apache\_backup_ directory’s files are successfully transferred to the apache\_backup directory on the receiving host.

![Verifying Transferred Files on the Receiving Host](https://adamtheautomator.com/wp-content/uploads/2022/05/image-610.png)

Verifying Transferred Files on the Receiving Host

## Sending Entire Disk or Partition to Another Host

Sending your entire disk or partition to another host may seem ambitious, but this task is achievable apart from sending files and directories. This feat comes in handy, especially if you need to backup your entire disk before taking drastic measures, such as moving or deleting tons of files.

1\. Run the command on the receiving host (ubuntu1) to start listening on port 4444. This command doesn’t have an output but unzips all the incoming data (bzip2 -d |dd) to /dev/sdb.

/dev/sdb is your second hard disk on the machine. But in this case, /dev/sdb is an empty hard disk attached to this machine for this tutorial.

```bash
netcat -l 4444 | bzip2 -d | dd of=/dev/sdb
```

2\. On the sending host (ubuntu2), run the below [fdisk](https://man7.org/linux/man-pages/man8/fdisk.8.html) command to find all the disks and partitions on your machine.

```bash
 fdisk -l
```

As you can see below, /dev/vda1/ is the root partition for the sending host in this tutorial. Your output may be different depending on your machine’s configuration.

![Finding All Disks and Partitions](https://adamtheautomator.com/wp-content/uploads/2022/05/image-611.png)

Finding All Disks and Partitions

3\. Run the following command on the sending host (ubuntu2), which doesn’t have an output, but sends the /dev/vda1 partition to the receiving host (ubuntu1) via port 4444.

Compressing and sending the partition to the receiving host takes a while, depending on the size of the partition.

```bash
bzip2 -c /dev/vda1 | netcat 149.28.86.131 4444
```

4\. Once the process completes, switch to the receiving host (ubuntu1), and you will see the output below.

The no space left on device error is expected since _/dev/vda1_ is probably larger than _/dev/sdb_. But you get the idea! You can use Netcat to send your entire hard disk or partition to another machine.

![Viewing the Sending Disk/Partition Process](https://adamtheautomator.com/wp-content/uploads/2022/05/image-612.png)

Viewing the Sending Disk/Partition Process

5\. Finally, run the commands on the receiving host (ubuntu1) to mount the /dev/vda1 partition and list all the files in the partition.

```bash
# Mounts /dev/vda1 partition
mount /dev/vda1 /media 
# Lists all the files in the partition
ls media
```

As you can see below, all files and directories from /dev/vda1 are successfully transferred to /dev/sdb.

![Verifying Data Integrity of the File Transfer](https://adamtheautomator.com/wp-content/uploads/2022/05/image-613.png)

Verifying Data Integrity of the File Transfer

## Creating a Minimal Webserver

Configuring a full-fledged web server like Apache or NGINX just to diagnose a web server issue can be a pain. Instead, create a minimal webserver with Netcat to quickly identify web server issues.

To create a minimal webserver:

1\. Switch to your received host and run the below commands to create a root directory (nc-webserver-docroot) for the webserver and a shell script (httpresponse.sh) that generates the HTTP response.

```bash
mkdir -pv /root/nc-webserver-docroot/
```

![Creating a Webserver Root Directory](https://adamtheautomator.com/wp-content/uploads/2022/05/image-614.png)

Creating a Webserver Root Directory

2\. Next, create an _index.html_ file in the _/root/nc-webserver-docroot/_ directory with your preferred editor and populate the file with the code below. This HTML file holds the contents that the Netcat web server will serve.

```bash
<!doctype html>

<html lang="en">

<head>
	<title>NETCAT Testing network connectivity </title>
</head>

<body>
	<h1>NETCAT Test</h1>
	<p>Connection Successful! Your networking skills are awesome!</p>
</body>

</html>
```

3\. Create a shell script file called _httpresponse.sh_ in the _/root/nc-webserver-docroot/_ directory and populate the code below.

This shell script returns the contents of the _/root/nc-webserver-docroot/index.html_ file as an HTTP response to any client that sends a request to your Netcat web server.

```bash
#!/bin/bash
printf 'HTTP/1.1 200 OK\n\n%s' "$(cat /root/nc-webserver-docroot/index.html)"
```

4\. Now, run the chmod command below, which doesn’t have an output but makes the httpresponse.sh file executable (+x).

```bash
chmod +x /root/nc-webserver-docroot/httpresponse.sh
```

Related:[Manage Directory and File Permissions with Chmod Recursive](https://adamtheautomator.com/chmod-recursive/)

5\. Run the below [ncat](https://man7.org/linux/man-pages/man1/ncat.1.html) command to start the Netcat web server on port 7777.

Be sure to replace port 7777 with the port number of your choice, which is not be used by any other service on your system.

The following options affect the behavior of stating the Netcat web server:

*   `-l` – tells Ncat to listen for an incoming connection.
    
*   `-v` – enables verbose mode to show all incoming HTTP requests in your terminal.
    
*   `-c - specifies the path to the _httpresponse.sh_ script that generates the HTTP responses.`
    
*   \-keep-open – keeps the Ncat listener open even after the first connection is closed. This option is useful if you test your web server with multiple clients.
    

```bash
ncat -lv 7777 -c /root/nc-webserver-docroot/httpresponse.sh --keep-open
```

You’ll see the following output once the Netcat web server runs and listens on port 7777 on all available network interfaces.

![Starting the Ncat Server](https://adamtheautomator.com/wp-content/uploads/2022/05/image-615.png)

Starting the Ncat Server

6\. Now, open another terminal and run the following command to test your Netcat web server (http://localhost:7777).

```bash
curl -vvv http://localhost:7777
```

The output below shows the Netcat web server is working as expected and can return the contents of the _/root/nc-webserver-docroot/index.html_ file as an HTTP response.

![Testing your Ncat server](https://adamtheautomator.com/wp-content/uploads/2022/05/image-616.png)

Testing your Ncat server

7\. Lastly, switch back to the terminal where the Netcat web server is running. You’ll see that the Netcat web server has received and processed the HTTP request from the curl client.

Congratulations! You’ve successfully created a minimal Netcat web server to test your networking connectivity!

![Verifying the HTTP Request from the curl Client](https://adamtheautomator.com/wp-content/uploads/2022/05/image-617.png)

Verifying the HTTP Request from the curl Client

## Conclusion

In this tutorial, you’ve learned to use Netcat to level up your networking and debugging skills. You’ve scanned for open ports, transferred files, and created a minimal web server. And at this point, you can now solve many real-world networking problems with this powerful networking utility!

With this newfound knowledge, why not level up your networking skills even more and become a power user in [Cybersecurity](https://www.youtube.com/watch?v=rdgv-EqyeAU)?

Share this article

[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fadamtheautomator.com%2Fhow-to-use-netcat%2F&text=How%20To%20Use%20Netcat%20and%20Level-Up%20Your%20Networking%20Skills!)[Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fadamtheautomator.com%2Fhow-to-use-netcat%2F)[Share on LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fadamtheautomator.com%2Fhow-to-use-netcat%2F)

## Related Posts

![](https://adamtheautomator.com/wp-content/uploads/2026/08/2026.08_Best-Practices-for-Building-a-Secure-New-Hire-Account-Activation-Workflow-1-e3df9fca.png)

### [Best Practices for Building a Secure New-Hire Account Activation Workflow](/secure-new-hire-account-activation/)

Onboarding is a uniquely high-risk process in that the IT department creates new identities and communicates with people who may not yet be fully embedded in

![](https://adamtheautomator.com/wp-content/uploads/2026/08/featured_image-2.webp)

### [Migrate Splunk to Sentinel Without Losing Detection Coverage](/splunk-to-sentinel-migration/)

A phased playbook for migrating Splunk to Microsoft Sentinel: audit detections, translate SPL to KQL, validate parity, and plan rollback.

![](https://adamtheautomator.com/wp-content/uploads/2026/08/featured_image.webp)

### [Entra PIM vs. Delinea vs. CyberArk: Don’t Buy the Wrong PAM](/entra-pim-vs-delinea-cyberark/)

Entra PIM grants roles; Delinea and CyberArk vault credentials. Compare scope, session recording, audit evidence, and three-year cost.

## Categories

*   [IT Ops](/category/it-ops/)
*   [Cloud](/category/cloud/)
*   [DevOps](/category/devops/)
*   [Home Ops](/category/home-ops/)
*   [Information Security](/category/infosec/)
*   [Software Development](/category/software-development/)

## Site

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Copyright 2026© ATA Learning | [Privacy Policy](/privacy/)
